MEDIUM 5.3 npm

Marked ReDoS due to email addresses being evaluated in quadratic time

GHSA-xf5p-87ch-gxw2

Published · Modified

Description

Versions of marked from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.

Recommendation

Upgrade to version 0.6.2 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes